4 ms·
If you want to know if a site is trustworthy, you want a certificate from their insurance company, not their CA. Someone who is promising to pay you real money
by voidmain 8y ago
If you want to know if a site is trustworthy, you want a certificate from their insurance company, not their CA. Someone who is promising to pay you real money if the site contains malware or a scam or whatever. Unfortunately this sort of insurance would probably be more, not less, expensive than EV certs.
- snowwrestler 8y agoThat type of insurance is often called cyber insurance, and is pretty common among businesses. I work for a nonprofit--not even a tech company--and we carry cyber insurance and require all our technology vendors to carry it too. Personally, I would not be opposed to CAs requiring proof of cyber insurance in order to issue an EV cert.
- voidmain 8y ago"Cyber insurance" may reimburse the site operator for the liability they have to you for (say) being infested with malware. And that model seems to work OK for car accidents. But I think that only helps you (the site visitor) if you already have a practical ability to sue the site operator (particularly difficult if the site operator is on the other side of the globe, in a jurisdiction you know nothing about). What I'm proposing is that the insurance company offers to accept direct liability to site visitors, with well defined liquidated damages and arbitration processes so that it actually means something to the user. If someone is offering that today, they aren't marketing it well. And again, actually signing the certificates would be a negligible part of the business (or the cost). Actually, if I were in the insurance business I'd actually think about pushing this direction. If you could get the browsers to sign up for giving it special treatment it would probably greatly increase the size of the market. (Right now operators seem to mostly just escape significant liability for compromises)